Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2010-0179

Published: 5 April 2010

Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.

Notes

AuthorNote
jdstrand
CVEs in Firefox are tracked in the xulrunner source packages. The
mapping of xulrunner sources to firefox is:
xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS
xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS
xulrunner-1.9: firefox-3.0
xulrunner-1.9.1: firefox-3.5
Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not
the system xulrunner-1.9.2, so it is tracked in the firefox source package.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
dapper Ignored
(reached end-of-life)
hardy Ignored
(uses system xulrunner)
intrepid Does not exist

jaunty Does not exist

karmic Does not exist

lucid Not vulnerable
(3.6.3+nobinonly-0ubuntu2)
maverick Not vulnerable
(3.6.3+nobinonly-0ubuntu2)
natty Not vulnerable
(3.6.3+nobinonly-0ubuntu2)
oneiric Not vulnerable
(3.6.3+nobinonly-0ubuntu2)
upstream
Released (3.6.3)
seamonkey
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy
Released (2.0.8+build1+nobinonly-0ubuntu0.8.04.1)
intrepid Needed
(reached end-of-life)
jaunty
Released (2.0.8+build1+nobinonly-0ubuntu0.9.04.1)
karmic
Released (2.0.8+build1+nobinonly-0ubuntu0.9.10.1)
lucid
Released (2.0.8+build1+nobinonly-0ubuntu0.10.04.1)
maverick Not vulnerable
(2.0.4+nobinonly-0ubuntu1)
natty Not vulnerable
(2.0.4+nobinonly-0ubuntu1)
oneiric Not vulnerable
(2.0.4+nobinonly-0ubuntu1)
upstream
Released (2.0.3)
xulrunner
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Ignored
(reached end-of-life)
intrepid Needed
(reached end-of-life)
jaunty Ignored
(reached end-of-life)
karmic Ignored
(reached end-of-life)
lucid Does not exist

maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream Needs triage

xulrunner-1.9
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy
Released (1.9.0.19+nobinonly-0ubuntu0.8.04.1)
intrepid
Released (1.9.0.19+nobinonly-0ubuntu0.8.10.1)
jaunty
Released (1.9.0.19+nobinonly-0ubuntu0.9.04.1)
karmic Does not exist

lucid Does not exist

maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream
Released (1.9.0.19)
xulrunner-1.9.1
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

intrepid Does not exist

jaunty
Released (1.9.1.9+nobinonly-0ubuntu0.9.04.1)
karmic
Released (1.9.1.9+nobinonly-0ubuntu0.9.10.1)
lucid Does not exist

maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream
Released (1.9.1.9)